CVE-2023-23931 affects the cryptography.io cryptography package, where the Cipher.update_into function incorrectly accepted immutable Python objects, such as bytes, and allowed them to be mutated. This flaw, present since cryptography 1.8, could lead to corrupted output by violating Python's fundamental immutability rules. Rated as Medium severity (CVSS 6.5), it has a low attack complexity and could result in low integrity and availability impacts. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.8, < 39.0.1CPE matchmatch criteria | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-23931
Jun 11, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024Splunk SOAR Cryptography Python Package Upgrade Incompatibility
Jul 17, 2023Cipher.update_into can corrupt memory in pyca cryptography
Feb 14, 2023python-cryptography: memory corruption via immutable objects
Feb 8, 2023Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Feb 7, 2023